Your feedback drives change, make your voice count
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
When configuring a FortiClient EMS server (v.7.4.1b1872) on Linux for Administrator SAML SSO with Entra/Azure it works if I use the default SP Address (<FQDN>), but we'll be locking down port 443 from external access and I would like to use 10443 for the SAML SSO. When configured the same way adding 10443 per the small blurb of instructions (<FQDN>:10443) it returns an EMS 404 error stating "The requested URL was not found on this server." If I reconfigure that same SAML entry to just the <FQDN>, updating the appropriate fields and certificate, it works. I have confirmed that port 10443 is open. The URL in the browser looks correct for the ACS link (https://<FQDN>:10443/saml/default/<UniqueKey>/acs). I don't see any issues off hand, and MS does report a successful log in. Attempting to log in as a unapproved user does result in the expected O365 "you do not have permission to log in" page. The server has been rebooted with the desired settings in
I need A support to get a fortigate VM Evaluation license for FFUMEUREFUFF9554
We just purchased a fortigate 70g firewall, and I am having some issues getting it connected to our existing network. For context the existing network consists of 3 cisco switches with multiple vlans setup. I have configured a Trunk port on the cisco switch and connected the fortigate to it, the issue I am having is getting the interface on the fortigate to talk to my network. What I want to have is 1 port act as the Mgmt port accessible by admin workstations thats on the "mgmt vlan", then have the various vlans added so i can give them internet access. What is the best way to go about this? Should i setup sub vlans interfaces on 1 physical port, or setup a vlan switch? This is my first fortigate so i am not familiar with it yet. Thanks.
Hi all,Yesterday I noticed that my FortiGate HA cluster went into an out-of-sync state.I tried recalculating the HA checksums on both nodes and also rebooted the secondary unit, but the cluster is still showing out of sync.Has anyone experienced this before? Is this a known bug in FortiOS 7.6.6, or is there another troubleshooting step I might be missing?FortiOS Version: 7.6.6 Build 3653Any advice would be appreciated. Thanks!
I’m trying to create a rule to allow traffic to a specific public domain or list of domains, from my internal users. Traffic that doesn’t match the “whitelisted” destination domain(s) should flow down through the existing rules. The following seems to be allowing all HTTP/HTTPS traffic, not just the traffic to the target domain. The Fortigate is running 7.2.13.If I enable the rule below, I see traffic in the log matching this rule, that is destined to all kinds of other domains. I don’t want to affect traffic to any other domains, and want traffic not destined to the “whitelisted” domains to just flow down through the other existing firewall rules.Ive tried using a “simple” URLfliter (as below) as well as a wildcard filter, but no matter what I’ve tried the rule seems to be matching way more traffic than I intend. config webfilter urlfilter............ edit 6 set name "Auto-webfilter-urlfilter_f7yxvxpub" config entries edit 1 set url "canv
Apologies for what I hope my struggles are merely from being a novice user of Fortigate products. I am now managing my first Fortigate 60E and trying to get port forwarding to work for a specific source. Actually, I do have port forwarding working for a specific source, but only one source. When I try to add any other source to a rule or even a separate rule for the source in question, it doesn’t work. I can’t remember if the source IP address that works was setup in some special way in the past, I am unable to find differences. So, I use the CLI to debug and really do not understand why the differences. First of all, here are the rules, both WebTent and WebTent DC are single IP addresses. As you can see, I am forwarding port 5022 to an internal IP port 22, this works from WebTent, but not WebTent-DC. So, for the debug, I see this for traffic when coming from WebTent and it works…FGT60ETK18001521 # diagnose debug flow filter saddr < my WebTent IP address >FGT60ETK18001521 # diagn
Hello everyone,I'm planning a maintenance window to upgrade the FortiGate firewalls in our environment, and I'd like to hear from those who have gone through a similar scenario.I've already completed an inventory of all devices, reviewed the Fortinet recommended firmware versions, and validated every upgrade path using the Fortinet Upgrade Path Tool. At this point, my questions are more about strategy than technical execution.Our current environment is as follows:Hostname Model Current Firmware Target Firmware FGT-HQ 70F 7.4.3 7.4.12 FGT-BR01 60E 7.4.3 7.4.12 FGT-BR02 60E 7.4.7 7.4.12 FGT-BR03 40F 7.4.11 7.4.12 FGT-BR04 40F 7.6.1 7.6.7 FGT-BR05 40F 7.6.6 7.6.7 FGT-BR06 40F 7.2.11 7.2.13 (or migrate to a newer branch) Additional information:Production environment. We use IPsec Site-to-Site VPNs, SD-WAN, security policies, NAT, VIPs, and SSL VPN. A full configuration backup will be taken before every upgrade. All firmware upgrades w
How do you transfer a call to someone’s voicemail? In this case, a secretary has her boss’ extension programmed as a soft key on her phone so she can answer it. A call comes in on her boss’ like, she answers, and would like to transfer it to her boss’ voicemail. Nothing I’ve found online seems to work (I’ve read dial *9 + extension, dial **9 + extension - neither work)…. Any suggestions?
Hi, I just downloaded the fortigateOS 7.6.7 into my GNS3,but when cli,i tryUsername:adminPassword:blank it fails to authenticateAnyone has any idea?
I have a Sectigo Certificate which i am trying to attach to admin GUI on port 443 ..i am not using any SSL VPN on the fortigates.. i built the file as leaf + intermediate + root and uploaded it under local → certificates.. additionally also uploaded intermediate separately under CA - Remote Certs .. but still when i try to check the cert validitiy via openssl or ssl labs it says that chain is missing and the chain is not reflecting at all.. i even tried attaching the certificate as a pfx but still the same issue.. any help is appreciated in resolving this.. Thanks
i purchased onr firewall model 40F before two days at 14-6-2026 , i found licenses activated since 2-2026 that mean i lost 4 months and i dont know that , seller did not tell me about that is there any solution please ?
Does agentless ZTNA work on Fortigate with eval license?because i am getting this error: wad_vs_find_cipher … ssl no matching CipherSuite
https://training.fortinet.com/
Hello everyone,I’m encountering an issue regarding batch account creation. I am using version v2.4.1-build0468. When I create a batch of users and try to email the created credentials, the email is sent correctly, but the attached Excel file is empty. It only contains the headers ('Username', 'Password') without any actual account data.%ACCOUNTLIST% in the email template doesn't seem to work either (it's blank in the email)In "Manage Account Batches", if I "Print account" it results in an error : "Unable to print/send details! Password not found for the user".So I literally have no way to get the password of the users.Surprisingly, “Random User Account Batch” works way better. The .csv contains the passwords & “Print account” actually works… Has anybody figured out how to create account batches using a .csv file (and get the list of the login/passwords)? Thanks in advance !
We have requirement to forward SD-WAN performance metrics, such as packet loss, latency, and threshold breach events, to the monitoring tool so that they can be effectively monitored and tracked.
Hi everyone,I have a question about renewing a Fortinet license that has been expired since 2024.My reseller is telling me that in order to regularize the situation, I have to take a license with 6 months of backdated prorata. Concretely, the license would start in January 2026, meaning that for a 1-year license purchased today (June 2026), I would only get 6 months of actual use until the end of 2026 — since the first 6 months (January to June 2026) have already passed.Is this really Fortinet's standard policy for expired licenses? Is it normal to have to pay for a period that has already elapsed when renewing late? Has anyone been in a similar situation, and is there any way to negotiate directly with Fortinet to get the start date set to the actual purchase date?Thanks in advance for your feedback!
Hi,I have FAZ FAZVM64-HV with v7.6.3 build3492 (Feature)when I login I see that nevest version is available to download - 7.6.7 (3737) I can’t upgrade this VM to nevest version.I am using FGT_VM64_HV-v7.6.7.M-build3704-FORTINET.out
I use FortiClient on Windows every day for VPN and other company resource access.When FortiClient opens in web browser, I type the one time password digit by digit and it works.When I connect to VPN with FortiClient, it opens from Windows system tray, and typing a digit doesn’t move to the next digit box, so I need to hit tab after each digit. I do this several times a day and it’s so annoying I felt I had to submit this. Please fix this!!!
Background: we've run out of 10gb ports on our switches and need to use on one the Fortigates.Was wondering if it's possible to bridge an existing Fortiswitch VLAN to one of the physical ports on the Fortigate.That way we can take advantage of the extra ports on the Fortigate.
Hello,I'm looking for an official clarification regarding the Layer 3 capabilities of the FortiSwitch FS-1048E.While reviewing the current FortiSwitch Campus Core and Data Center Series datasheet, I noticed what appears to be conflicting information:In the FortiLink Mode (with FortiGate) feature table, it states: "L3 Routing and Services (FortiGate)" "Policy-Based Routing (FortiGate)" This seems to imply that Layer 3 routing is only available when the switch is managed by a FortiGate through FortiLink.However, in the Layer 3 Features section, the FS-1048E is listed as supporting: Static Routing (Hardware-based) OSPF RIP VRRP BGP ISIS VRF ECMP Policy-Based Routing and other L3 capabilities (some requiring the Advanced Features License). The hardware specifications also explicitly list IPv4/IPv6 Routing for the FS-1048E.My question is:Does the FS-1048E support Layer 3 routing in standalone mode, without being managed by a FortiGate via FortiLink? If yes, are there any feature
Now i make authentication in fortinac using persistent agent and passive agent and i configure LoginDialogDisabled to hide the popup login credentials but it still appears for first time user appears although i configure everything as per below article can anyone advise if faces this problem
Hello everyone. We bought a Fortigate 71g (7.6.7). I have experience using OpenVPN on Mikrotik and Pfsense. It was very convenient for remote access and local DNS access. The point is, we need to provide remote access to people without providing a DNS domain and server; we bind users by IP addresses, and that was sufficient. The problem is that I can't get the IPSec Fortigate to work without providing clients with a DNS server. All requests start going through the VPN tunnel, and access to local domains and DNS is lost.Detecting the client's local DNS is not quite right. For example, OpenVPN has this block-outside-dns feature. Is there a solution?Tried:1) config vpn ipsec phase1-interface edit "test1" set dns-mode manual set ipv4-dns-server1 0.0.0.0 nextend2) I tried unset ipv4-dns-server1,2,33) ipsec Mode config - manual4) in the client's config in XML: <ipsecvpn> <options> <enabled>1</enabled>
Please help meI want to set it up like this: I have FortiGate, a Ruijie managed switch, and several APs. FortiGate port 3 will connect to the switch, and the APs will connect to the switch as well. I want mobile devices connected to the APs to be on the same IP subnet as the FortiGate and Ruijie.
Hi all,I can see lots of posts about dual wan connections on the Fortigate with lots of solutions for different scenarios, however I'd still like some advice with my situation.We have a Fortigate 81F (firmware 7.4.12) at the main office. It currently has one internet link (wan1). This is used for internet traffic, as well as ipsec vpn from 4 remote sites. These remote sites also use the Fortigate wan1 as their internet connection.We are using ospf to advertise routes between the main office and remote sites. The Fortigate's default route is via our isp.We wish to get a second internet connection to connect to wan2. This will be solely for the ipsec vpn; no link redundancy or load balancing (at this stage, perhaps in the future). All internet access will be via wan1.In what I hope is a simple situation like this, would setting static routes to both wan1 and wan2 but setting a higher priority on wan2 be enough to prevent atttempts to use wan2 as the internet link?I see other option
The MyCanal website used to work on my site, but now it doesn't. When I check on my Forti account, I see that it's blocked. So I want to understand why Forti is blocking MyCanal now and what I should do.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.